Solution: XSS Challenges (by yamagata21) – Stage #11

In this lab, “script”, “style” and all events with “on…” will be replaced, so we will create a link like we did in stage 8 and use a horizontal tab (&#x09) to separate “s” and “cript“.

"><a href="javas	cript:alert(document.domain)">

Then, we click the link.

Leave a comment

Design a site like this with WordPress.com
Get started